Metabase SQLi exploit grants attackers total access
Summary
Business intelligence platform Metabase has disclosed a critical zero-day SQL injection vulnerability, CVE-2026-72898, affecting versions 1.58 and up. Attackers can exploit this flaw to gain unmitigated access to sensitive data within the Metabase database, including credentials and tokens. Metabase has patched the vulnerability and urges self-hosted customers to apply the update.
IFF Assessment
The discovery of a critical zero-day SQL injection vulnerability with a perfect CVSS score signifies a major security risk that could lead to widespread data compromise.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: August 14, 2026. Known ransomware use: Unknown.
Defender Context
This critical SQL injection vulnerability in Metabase presents a significant risk to organizations utilizing the platform for business intelligence. Defenders must prioritize patching self-hosted instances immediately and audit for any signs of compromise. The exploit's ease of use and the sensitive data it can expose make it a prime target for attackers.